Denial of Service Vulnerability in Cisco IoT Field Network Director
CVE-2026-20167

7.7HIGH

Key Information:

Vendor

Cisco

Vendor
CVE Published:
6 May 2026

Badges

👾 Exploit Exists

What is CVE-2026-20167?

A security flaw in the web-based management interface of Cisco IoT Field Network Director allows an authenticated, low-privileged attacker to exploit improper error handling. By sending specially crafted input, the attacker can initiate a denial of service condition on a remotely managed router, potentially causing it to reload and making it unavailable for legitimate users. This risk highlights the importance of robust error handling and secure management practices in IoT environments.

Affected Version(s)

Cisco IoT Field Network Director (IoT-FND) 4.5.1

Cisco IoT Field Network Director (IoT-FND) 4.4.3

Cisco IoT Field Network Director (IoT-FND) 4.1.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.